• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (c) 2008 Patrick McHardy <kaber@trash.net>
3  *
4  * This program is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License version 2 as
6  * published by the Free Software Foundation.
7  */
8 
9 #include <linux/types.h>
10 #include <linux/sctp.h>
11 #include <net/sctp/checksum.h>
12 
13 #include <net/netfilter/nf_nat_l4proto.h>
14 
15 static u_int16_t nf_sctp_port_rover;
16 
17 static void
sctp_unique_tuple(const struct nf_nat_l3proto * l3proto,struct nf_conntrack_tuple * tuple,const struct nf_nat_range * range,enum nf_nat_manip_type maniptype,const struct nf_conn * ct)18 sctp_unique_tuple(const struct nf_nat_l3proto *l3proto,
19 		  struct nf_conntrack_tuple *tuple,
20 		  const struct nf_nat_range *range,
21 		  enum nf_nat_manip_type maniptype,
22 		  const struct nf_conn *ct)
23 {
24 	nf_nat_l4proto_unique_tuple(l3proto, tuple, range, maniptype, ct,
25 				    &nf_sctp_port_rover);
26 }
27 
28 static bool
sctp_manip_pkt(struct sk_buff * skb,const struct nf_nat_l3proto * l3proto,unsigned int iphdroff,unsigned int hdroff,const struct nf_conntrack_tuple * tuple,enum nf_nat_manip_type maniptype)29 sctp_manip_pkt(struct sk_buff *skb,
30 	       const struct nf_nat_l3proto *l3proto,
31 	       unsigned int iphdroff, unsigned int hdroff,
32 	       const struct nf_conntrack_tuple *tuple,
33 	       enum nf_nat_manip_type maniptype)
34 {
35 	struct sctphdr *hdr;
36 	int hdrsize = 8;
37 
38 	/* This could be an inner header returned in imcp packet; in such
39 	 * cases we cannot update the checksum field since it is outside
40 	 * of the 8 bytes of transport layer headers we are guaranteed.
41 	 */
42 	if (skb->len >= hdroff + sizeof(*hdr))
43 		hdrsize = sizeof(*hdr);
44 
45 	if (!skb_make_writable(skb, hdroff + hdrsize))
46 		return false;
47 
48 	hdr = (struct sctphdr *)(skb->data + hdroff);
49 
50 	if (maniptype == NF_NAT_MANIP_SRC) {
51 		/* Get rid of src port */
52 		hdr->source = tuple->src.u.sctp.port;
53 	} else {
54 		/* Get rid of dst port */
55 		hdr->dest = tuple->dst.u.sctp.port;
56 	}
57 
58 	if (hdrsize < sizeof(*hdr))
59 		return true;
60 
61 	if (skb->ip_summed != CHECKSUM_PARTIAL) {
62 		hdr->checksum = sctp_compute_cksum(skb, hdroff);
63 		skb->ip_summed = CHECKSUM_NONE;
64 	}
65 
66 	return true;
67 }
68 
69 const struct nf_nat_l4proto nf_nat_l4proto_sctp = {
70 	.l4proto		= IPPROTO_SCTP,
71 	.manip_pkt		= sctp_manip_pkt,
72 	.in_range		= nf_nat_l4proto_in_range,
73 	.unique_tuple		= sctp_unique_tuple,
74 #if IS_ENABLED(CONFIG_NF_CT_NETLINK)
75 	.nlattr_to_range	= nf_nat_l4proto_nlattr_to_range,
76 #endif
77 };
78